Analytics BIOC Informational

Microsoft Teams external communication policy was modified

Microsoft Teams external communication policy was modified.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Office 365 Audit
ATT&CK tactics: Defense Evasion (TA0005) Exfiltration (TA0010)
ATT&CK techniques: Impair Defenses (T1562) Exfiltration Over Alternative Protocol (T1048)
Detector tags: Microsoft Teams
Attacker's goals:

Attackers may modify the external communication policy to enable data exfiltration or to hide their activities.

Investigative actions:

Determine if it is within the user's role to modify the policy. Verify whether the modification of the policy is both legitimate and necessary. Follow further communication with the external tenant or allowed tenants. Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Microsoft Teams external communication policy was modified by an unusual user Low (parent: Informational)